Privacy Policy
Last updated 25 September 2026
1. Who is responsible
CareerTrends is operated by Tenzin Choedak, an individual seller in the United States. That person is the controller of the personal data described here. Write to support@careertrends.io for anything on this page.
2. What we collect
Sign-in identity. When you sign in with Google through Auth0, we receive and store the identity subject your provider asserts, your verified email address, and your display name. The subject is what identifies your account.
Your workspace. The companies on your watchlist, any saved role and location searches, any new-company coverage requests you submit, and whether you have opted in to the weekly email digest.
Billing. If you subscribe, we store the Stripe customer identifier, the subscription identifier, its status, its period end date and whether it is set to cancel at period end. We never receive or store card numbers, bank details or the security code: those are entered on Stripe-hosted pages and stay with Stripe.
Session records. A random session token is placed in a cookie; the database stores only a hash of it, together with an expiry date.
Email delivery records. When a digest or a support message is sent, we record a key and whether delivery succeeded. A digest key contains your account number and the date of the send; a support key is random. Neither contains the message body or your email address.
Server logs. Only requests that fail or are rate-limited are recorded, and only with a request identifier, the path, the response status and how long the request took. Ordinary page and API requests are not recorded at all. We keep no log file of our own: these lines go to the hosting platform's log stream and are not copied anywhere else.
Analytics. The company explorer loads DataFast, a cookieless analytics service. It records page views; it does not set advertising cookies and it is not used to build a profile of you across other sites.
3. What we do not collect
We collect job data only from public job-board APIs - Greenhouse, Lever and Ashby. We do not collect applicant data, and we do not connect to any private system, recruiter account or credential. We do not run advertising trackers, and we do not sell personal data.
4. Who we share it with
We use a small set of processors, each for one job:
- Auth0 and Google - signing in and verifying your identity.
- Stripe - taking payments, managing the subscription, and handling refunds and disputes.
- Resend - delivering the weekly digest and support email.
- Fly.io - hosting the application and storing the database.
- DataFast - cookieless page-view analytics on the explorer.
We may also disclose data where the law requires it, or where it is needed to protect the service or someone's safety. If the business is ever sold or transferred, account data would move with it and this page would be updated first.
5. How long we keep it
Account data is kept while your account exists. You can delete your account yourself, without asking us, from your account page. Deletion takes effect immediately in the live database and removes your session records, watchlist, saved searches, coverage requests and digest delivery records. Copies taken before you delete can hold your data for up to 30 days before they age out.
If your account has a payment record, we keep that record - the Stripe customer and subscription identifiers, the status and the period dates - for 6 months after deletion, so that refunds, chargebacks and accounting stay reconcilable. When we keep that record we first remove your email address, your display name, your digest preference, and the identity subject that could link the record back to you. The identifier we retain is meaningless outside Stripe. After the 6 months, the account row and the payment record are deleted automatically.
Operational records that are not tied to your account have a shorter window of their own: crawl runs and the failure messages they carry, payment webhook identifiers, and email delivery records are deleted after 30 days. A delivery that has not yet completed is kept until it completes.
The job-posting history itself is not a record about you. It is counts collected from public job boards, and it is kept for as long as a company is tracked, because the whole product is how that history changes.
6. Your choices and your rights
- Delete. Self-serve and immediate, from your account page. If a subscription is still active you must cancel it first, because deleting the account would otherwise leave you paying with no account in which to see it.
- Unsubscribe. Turn the weekly digest off in your account at any time; it is off unless you turn it on.
- Correction or objection. Write to support@careertrends.io.
We do not use your data for automated decision-making that produces legal or similarly significant effects.
7. Security
Sessions use opaque random tokens, stored only as hashes, in HttpOnly and SameSite cookies, over HTTPS. Admin and consumer sessions are entirely separate. Whether you have Member access is enforced on the server from verified payment state, never from anything the browser sends. Card details never reach our servers.
No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will tell affected account holders and any regulator we are required to notify.
8. Children
The service is not intended for anyone who cannot enter into a binding contract where they live, and we do not knowingly collect their personal data. If you believe a child has created an account, write to us and we will remove it.
9. Changes to this policy
When this policy changes materially we will update the date at the top of the page and tell account holders in the product before the change takes effect.
10. Contact
Privacy questions and requests: support@careertrends.io. See also Contact.